Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Container Registry
  • Getting started
    • All guides
    • Installing and configuring Docker
    • Authentication in Container Registry
      • Getting information about existing lifecycle policies
      • Creating a lifecycle policy
      • Updating a lifecycle policy
      • Performing a lifecycle policy dry run
      • Deleting a lifecycle policy
    • Scanning Docker images for vulnerabilities
    • Creating a trigger for a registry
  • Yandex Container Solution
  • Access management
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Troubleshooting
  • FAQ
  1. Step-by-step guides
  2. Managing Docker image lifecycle policies
  3. Creating a lifecycle policy

Creating a lifecycle policy

Written by
Yandex Cloud
Improved by
Danila N.
Updated at August 10, 2026
View in Markdown

You can only set a lifecycle policy for a repository. To find out the repository name, get a list of repositories in the registry.

Management console
CLI
Terraform
API
  1. In the management console, select the folder with the registry.
  2. Navigate to Container Registry.
  3. Select the registry and click the row with its name.
  4. Select the repository and click the row with its name.
  5. In the left-hand panel, click Lifecycle.
  6. In the top-right corner, click Create.
  7. Configure the lifecycle policy settings:
    • Name. This is an optional setting.
    • Description. This is an optional setting.
    • Status: Lifecycle policy status after creation. We do not recommend creating an ACTIVE policy right away.
    • Under Lifecycle policy rules, add rules:
      1. Click Add.

      2. Configure the rule:

        • Tag regexp: Docker image tag for filtering. Java regular expressions are supported. For example, the test.* regular expression retrieves all images with tags starting with test.
        • Untagged: Flag to apply the rule to untagged Docker images.
        • Expire period, in days: Time after which the lifecycle policy may apply to the Docker image.
        • Retained top: Number of Docker images that will not be deleted even if they match the rule.
        • Description. This is an optional setting.
  8. Click Create.

If you do not have the Yandex Cloud CLI yet, install and initialize it.

  1. Set up policy rules and save them to a file named rules.json.

    Example of the contents of a file with rules, where:

    • description: Description of the policy rule.
    • tag_regexp: Docker image tag for filtering. Java regular expressions are supported. For example, the test.* regular expression retrieves all images with tags starting with test.
    • untagged: Flag to apply the rule to untagged Docker images.
    • expire_period: Time after which the lifecycle policy may apply to the Docker image. This parameter comes as a number followed by a unit of measurement: s, m, h, or d (seconds, minutes, hours, or days). expire_period must be a multiple of 24 hours.
    • retained_top: Number of Docker images that will not be deleted even if they match the rule.
    [
      {
        "description": "delete prod Docker images older than 60 days but retain 20 last ones",
        "tag_regexp": "prod",
        "expire_period": "60d",
        "retained_top": 20
      },
      {
        "description": "delete all test Docker images except 10 last ones",
        "tag_regexp": "test.*",
        "retained_top": 10
      },
      {
        "description": "delete all untagged Docker images older than 48 hours",
        "untagged": true,
        "expire_period": "48h"
      }
    ]
    
  2. Create a lifecycle policy by running this command:

    yc container repository lifecycle-policy create \
      --repository-name crp3cpm16edq********/ubuntu \
      --name test-policy \
      --description "disabled lifecycle-policy for tests" \
      --rules ./rules.json
    

    Where:

    • --repository-name: Repository name.

    • --rules: Path to the policy description file.

    • --description: Lifecycle policy description. This is an optional setting.

    • --name: Policy name. This is an optional setting. The naming requirements are as follows:

      • Length: between 3 and 63 characters.
      • It can only contain lowercase Latin letters, numbers, and hyphens.
      • It must start with a letter and cannot end with a hyphen.

    Note

    By default, the policy is created with the DISABLED status. We do not recommend creating an active policy (with the --active flag) right away.

    Result:

    id: crp6lg1868p3********
    name: test-policy
    repository_id: crp3cpm16edq********
    ...
    - description: delete all untagged Docker images older than 48 hours
      expire_period: 172800s
      untagged: true
    

    The value of the expired_period parameter in the response is shown in seconds. This is a technical constraint; the format will be changed.

  3. Make sure the policy has been created by running the following command:

    yc container repository lifecycle-policy list --repository-name crp3cpm16edq********/ubuntu
    

    Where --repository-name is the repository name.

    Result:

    +----------------------+-------------+----------------------+----------+---------------------+-------------------------------+
    |          ID          |    NAME     |    REPOSITORY ID     |  STATUS  |       CREATED       |          DESCRIPTION          |
    +----------------------+-------------+----------------------+----------+---------------------+-------------------------------+
    | crp6lg1868p3******** | test-policy | crp3cpm16edq******** | DISABLED | 2020-05-28 15:05:58 | disabled lifecycle-policy for |
    |                      |             |                      |          |                     | tests                         |
    +----------------------+-------------+----------------------+----------+---------------------+-------------------------------+
    

If you do not have Terraform yet, install it and configure the Yandex Cloud provider.

To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.

  1. In the configuration file, specify the properties of the resources you want to create:

    resource "yandex_container_repository_lifecycle_policy" "my_lifecycle_policy" {
      name          = "<policy_name>"
      status        = "<policy_status>"
      repository_id = "<repository_ID>"
    
      rule {
        description   = "<rule_description>"
        untagged      = true
        tag_regexp    = ".*"
        retained_top  = 1
        expire_period = "48h"
      }
    }
    

    Where:

    • name: Policy name.
    • status: Policy status. It can be either active or disabled.
    • repository_id: Repository ID.
    • rule: Policy rule section. It contains the following:
      • description: Rule description.
      • untagged: If this parameter is set to true, the rule applies to all Docker images that do not have a tag.
      • tag_regexp: Docker image tag for filtering. Java regular expressions are supported. For example, the test.* regular expression retrieves all images with tags starting with test.
      • retained_top: Number of Docker images that will not be deleted even if they match the lifecycle policy rules.
      • expire_period: Time after which the lifecycle policy applies to the Docker image. This parameter comes as a number followed by a unit of measurement: s, m, h, or d (seconds, minutes, hours, or days). expire_period must be a multiple of 24 hours.

    For more on the properties of the yandex_container_repository_lifecycle_policy resource, see this provider guide.

  2. Create the resources:

    1. In the terminal, navigate to the configuration file directory.

    2. Make sure the configuration is correct using this command:

      terraform validate
      

      If the configuration is valid, you will get this message:

      Success! The configuration is valid.
      
    3. Run this command:

      terraform plan
      

      You will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.

    4. Apply the configuration changes:

      terraform apply
      
    5. Type yes and press Enter to confirm the changes.

This will create a lifecycle policy in the specified repository. You can check the new policy and its settings using the management console or this CLI command:

 yc container repository lifecycle-policy list --registry-id <registry_ID>

To create a lifecycle policy, use the Create method for the LifecyclePolicyService resource.

Tip

You can test the lifecycle policy to see which Docker images match the policy rules. Docker images are not actually deleted during dry runs.

Was the article helpful?

Previous
Getting information about existing lifecycle policies
Next
Updating a lifecycle policy
© 2026 Direct Cursus Technology L.L.C.